๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:35
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-15 01:39:03
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ญ
TheCoon
2026-06-15 00:45:01
(5 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 00:38:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:38:44.614341 2026] [security2:error] [pid 31019:tid 31039] [client 34.19.136.25:34660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gqsi.org"] [uri "/app/.git/config"] [unique_id "ai9JlLHkKShrBaxWMMY1GAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NihiliousMonk
2026-06-14 23:37:21
(5 days ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:36:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:36:26.601567 2026] [security2:error] [pid 23868:tid 23868] [client 34.19.136.25:50434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamedayincentives.com"] [uri "/app/.git/config"] [unique_id "ai86-npJ9FPISvxggTPhWwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-14 22:24:07
(5 days ago)
[MonJun1500:24:01.6305162026][security2:error][pid3364310:tid3364314][client34.19.136.25:0]ModSecuri ...
show more
[MonJun1500:24:01.6305162026][security2:error][pid3364310:tid3364314][client34.19.136.25:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"allegraravizza.it\"][uri\"/v3/.git/config\"][unique_id\"ai8qActimeK0es7A4q7LZwAAAEE\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-06-14 22:04:11
(5 days ago)
CrowdSec:crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-14 21:59:44
(5 days ago)
Auto-ban: >3000 req/min op 2026-06-14
Web App Attack
SSH
Hacking
๐ณ๐ฟ
Antinson
2026-06-14 21:56:01
(5 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
alecj.com
2026-06-14 21:03:12
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ฟ
huginet
2026-06-14 13:22:04
(6 days ago)
34.19.136.25 - - [14/Jun/2026:15:22:03 +0200] "GET /.git/config HTTP/1.1" 403 32175 "-" "Mozilla/5.0 ...
show more
34.19.136.25 - - [14/Jun/2026:15:22:03 +0200] "GET /.git/config HTTP/1.1" 403 32175 "-" "Mozilla/5.0 (iPad; CPU OS 10_0 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/49.0.2623.109 Mobile/14A5335b Safari/601.1.46"
34.19.136.25 - - [14/Jun/2026:15:22:03 +0200] "GET /v1/.git/config HTTP/1.1" 403 32175 "-" "Mozilla/5.0 (Linux; Android 9; Redmi Note 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.89 Mobile Safari/537.36"
...
show less
Web Spam
Web App Attack
๐จ๐ญ
Ribeye375
2026-06-14 06:28:24
(6 days ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-14 05:55:46
(6 days ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:45:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.136.25 (25.136.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:44:55.653707 2026] [security2:error] [pid 17828:tid 17828] [client 34.19.136.25:60248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dutchgreenrecycling.com"] [uri "/v3/.git/config"] [unique_id "ai4_1yYDi2qW-tyzkXFbLwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack